Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Scorecard supply-chain security#106

Scorecard supply-chain security

Scorecard supply-chain security #106

Workflow file for this run

name:Scorecard supply-chain security
on:
# For Branch-Protection check. Only the default branch is supported. See
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#branch-protection
branch_protection_rule:
# To guarantee Maintained check is occasionally updated. See
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
schedule:
-cron:'36 17 * * 5'
push:
branches:[ "main" ]
# Declare default permissions as read only.
permissions:read-all
jobs:
analysis:
name:Scorecard analysis
runs-on:ubuntu-latest
permissions:
security-events:write# to upload the results to code-scanning dashboard
id-token:write# to publish results and get a badge
steps:
-name:"Checkout code"
uses:actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8# v5.0.0
with:
persist-credentials:false
-name:"Run analysis"
uses:ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde# v2.4.2
with:
results_file:results.sarif
results_format:sarif
# To enable Branch-Protection uncomment the `repo_token` line below
# To create the Fine-grained PAT, follow the steps in https://github.com/ossf/scorecard-action#authentication-with-fine-grained-pat-optional.
# repo_token: ${{ secrets.SCORECARD_TOKEN }}
publish_results:true# allows the repo to include the Scorecard badge
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
-name:"Upload artifact"
uses:actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02# v4.6.2
with:
name:SARIF file
path:results.sarif
retention-days:5
# Upload the results to GitHub's code scanning dashboard.
-name:"Upload to code-scanning"
uses:github/codeql-action/upload-sarif@192325c86100d080feab897ff886c34abd4c83a3# v3.30.3
with:
sarif_file:results.sarif

[8]ページ先頭

©2009-2025 Movatter.jp